Identity proofing is often a prerequisite for accessing important services (e.g., opening a bank account). The current pandemic has highlighted the need for remote identity proofing (RIDP) that can enable applicants to prove their identity from anywhere, without the need for a special facility. However, the requirements set out by the National Institute of Standards and Technology for the highest level of assurance in RIDP systems currently rule out fully automated and remote solutions, as they are not yet foolproof. This article aims to propose a way forward for pervasive RIDP solutions and highlights the requirements for accomplishing the highest level of assurance in verifying identity. We pinpoint relevant issues and threats along with the current state-of-the-art countermeasures and discuss what else needs to be done to enable ubiquitous remote identity-proofing systems.
Physical authentication devices (PADs) offer a higher level of security than other authentication technologies commonly used in multifactor authentication (MFA) schemes because they are much less vulnerable to attack. However, PAD uptake remains significantly lower than that for SMS and app-based approaches, accounting for only 10% of all authentication technologies currently being utilized in MFA. Prior studies indicate that the primary reason for this low adoption rate is due to negative users' perceptions and attitudes toward the usability of PADs; many of these studies often skew toward a particular set of users (e.g., young university students, etc.), often creating a bias toward what usable security entails. To address this limitation, we have formulated an original research methodology that segments users into specific groups based on their user characteristics (i.e., age, education, and experience) and examines how each group defines usability and ranks their preferences regarding certain security features. Based on a survey of 410 participants, our results indicate that there are indeed different usable security preferences for each user group, and we, therefore, provide recommendations on how existing PADs might be enhanced to support usability and improve adoption rates.
Advanced persistent threat (APT) is widely acknowledged to be the most sophisticated and potent class of security threat. APT refers to knowledgeable human attackers that are organized, highly sophisticated and motivated to achieve their objectives against a targeted organization(s) over a prolonged period. Strategically-motivated APTs or S-APTs are distinct in that they draw their objectives from the broader strategic agenda of third parties such as criminal syndicates, nation-states, and rival corporations. In this paper we review the use of the term “advanced persistent threat,” and present a formal definition. We then draw on military science, the science of organized conflict, for a theoretical basis to develop a rigorous and holistic model of the stages of an APT operation which we subsequently use to explain how S-APTs execute their strategically motivated operations using tactics, techniques and procedures. Finally, we present a general disinformation model, derived from situation awareness theory, and explain how disinformation can be used to attack the situation awareness and decision making of not only S-APT operators, but also the entities that back them.
The modern digital world of networking and connectivity enabled by the Internet of Things (IoT) has the paradoxical result of introducing a new era of 'smart computing' while reducing the intelligent control that individuals can exercise over their personal data. In this digital realm of big data and predictive analytics, we argue that users should be able to exert greater control over the collection, storage and use of their personal data. Our focus groups with IoT designers and users indicate that they are worried about the handling of their data, with users voicing concerns including surveillance and insecure storage of their data in the Cloud. Overall users wish for greater involvement in the management of their data. In response, we propos ea high-level design prototype of an Intelligent Warning Application ('IWA') titled 'DataMind',empowering users to better control their IoT data collection, storage and use through: i) registering devices they wish to control; ii) setting and controlling required risk levels of their personal data flows; and iii) reacting on app warnings in the form of 'technological nudges' that report risky data flows. We present three illustrating scenarios of the latter together with corrective user actions, and conclude with a discussion of further steps of the design of this app.
In collaboration with the International Telecommunication Union (ITU), the Global Cyber Security Capacity Centre (GCSCC, or ‘the Centre’) together with its regional partner, the Oceania Cyber Security Centre (OCSC) undertook a review of the maturity of cybersecurity capacity in the Independent State of Samoa at the invitation of the Ministry of Communications and Information Technology (MCIT). The objective of this review was to enable the government of Samoa to benchmark national cybersecurity capacity and set priorities for strategic investment and capacity development.Over the period 18-20 April 2018, the following stakeholders participated in roundtable consultations: academia, criminal justice, law enforcement, information technology officers and representatives from public-sector entities, critical-infrastructure owners, policy makers, information-technology officers from the government and the private sector (including financial institutions), the banking sector, as well as international partners.
The Internet of Things (IoT) is considered to be one of the most significant disruptive technologies of modern times, and promises to impact our lives in many positive ways. At the same time, its interactivity and interconnectivity poses significant challenges to privacy and data protection. Following an exploratory interpretive qualitative case study approach, we interviewed 14 active IoT users plus ten IoT designers/developers in Melbourne, Australia to explore their experiences and concerns about privacy and data protection in a more networked world enabled by the IoT. We conclude with some recommendations for ‘responsive regulation’ of the IoT in the Australian context.
The modern digital world of networking and connectivity makes pos-sible a new era of computing in which users exert greater control over the col-lection and use of their personal data through the Internet of Things (IoT). Our recent empirical work indicates that traditional forms of consent are inadequate and that users are looking for different levels of and greater involvement in con-Trolling the collection and use of their personal data - with some participants voicing particular concerns about collection and use of sensitive data, such as health information, and others pointing to particular risks, such as insecure stor-Age in the Cloud. In response to these needs we propose a new Intelligent Warn-ing Application in the form of a conceptual architecture for an App that em-powers users to control their IoT data collection through users: 1) identifying their own levels of risk, 2) customizing the App allowing for the setting of their identified risk levels, and 3) situated use of the App warning users of risk-Averse situations through 'nudges'. We conclude with a discussion illustrating scenarios of the App's.
The security-related experiences of Incident Response Teams provide Enterprise Information Security Management with a unique opportunity to draw lessons and insights. However, research has shown that there is often inadequate informationsharing between the security and response functions of organizations. In this paper we apply a general theory of organizational learning to interpret findings from a case study of IR practices at a major Australian financial institution, and then propose a learning process model that can be used to bridge IR and ISM functions in organizations. Findings from focus group research carried out for preliminary evaluation of the model are presented, followed by a discussion of the project’s next steps.
Information security risk management (ISRM) is the primary means by which organizations preserve the confidentiality, integrity and availability of information resources. A review of ISRM literature identified deficiencies in the practice of information security risk assessment that inevitably lead to poor decision-making and inadequate or inappropriate security strategies. In this conceptual paper, we propose a situation aware ISRM (SA-ISRM) process model to complement the information security risk management process. Our argument is that the model addresses the aforementioned deficiencies through an enterprise-wide collection, analysis and reporting of risk-related information. The SA-ISRM model is adapted from Endsley's situation awareness model and has been refined using our findings from a case study of the US national security intelligence enterprise.
Three deficiencies exist in the organisational practice of information security risk management: risk assessments are commonly perfunctory, security risks are estimated without investigation; risk is assessed on an occasional (as opposed to continuous) basis. These tendencies indicate that important data is being missed and that the situation awareness of decision-makers in many organisations is currently inadequate. This research-in-progress paper uses Endsley's situation awareness theory, and examines how the structure and functions of the US national security intelligence enterprise—a revelatory case of enterprise situation awareness development in security and risk management—correspond with Endsley’s theoretical model, and how facets of the US enterprise might be adapted to improve situation awareness in the information security risk management process of organisations.
Three deficiencies exist in information security under prevailing practices: organisations tend to focus on compliance over protection; to estimate risk without investigating it; and to assess risk on an occasional (as opposed to continuous) basis. These tendencies indicate that important data is being missed and that the situation awareness of decision-makers in many organisations is currently inadequate. This research-in-progress paper uses Endsley's situation awareness theory, and examines how the structure and functions of the US national security intelligence enterprise—a revelatory case of enterprise situation awareness development in security and risk management—correspond with Endsley’s theoretical model, and how facets of the US enterprise might be adapted to improve situation awareness in the information security risk management process of organisations.